matomo.documentfoundation.org - malicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned matomo.documentfoundation.org and returned a malicious verdict (score 61), categorised as credential-harvest. The page resolved to 157.90.183.190 on Hetzner Online GmbH in DE. The domain was registered 5816 days ago through Key-Systems GmbH. 2 domains and 1 IP were contacted, over 5 HTTP requests. 9 malware samples communicate with this URL (Container, RedLine). The request followed 1 redirect before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 61) · Confidence 70%
- Scanned URL:
https://piwik.documentfoundation.org/ - Domain: matomo.documentfoundation.org · IP: 157.90.183.190 · AS24940 · DE
- Server: nginx
- Page title: Sign in - Matomo
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: Key-Systems GmbH · domain age 5816 days · created 2010-09-15
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 26 02: · subject CN=matomo.documentfoundation.org
- HTTP requests captured: 5
- Scan tier: fast · observed 2026-08-19 15:58:23 UTC
Redirect chain
https://piwik.documentfoundation.org/https://matomo.documentfoundation.org/
Malware communicating with this URL (9)
These samples were observed contacting or being served from matomo.documentfoundation.org. Each links to its full analysis.
- Container - referenced ·
69843b6c9f1db6f7acadd911655b6b36· first seen 2026-08-19 - RedLine - referenced ·
48ebbc59602bbaf1be62b11a81b7da0d· first seen 2026-08-19 - Container - referenced ·
4ab9579801e5438ec38e640cf534b528· first seen 2026-08-19 - Container - referenced ·
5dfe32659fdb9c731bbce59ec14e75ac· first seen 2026-08-19 - Container - referenced ·
1c8dd068142c4e63f041b1f1b8d4f9b4· first seen 2026-08-19 - Container - referenced ·
79b06debc112e2ef2fc42870da69136b· first seen 2026-08-19 - Container - referenced ·
2160c2c235a889f451d4ae8088c8914f· first seen 2026-08-18 - Container - referenced ·
89cb952b1e67ca9b3bebb9e6e49bab6c· first seen 2026-08-18 - Container - referenced ·
3ed872eac04129a65cc4332c674a46ca· first seen 2026-08-18
Antivirus & YARA (2 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
Categories
- credential-harvest
Why this verdict
- 2 antivirus/YARA engines flagged the page content: DLV_HTML_Smuggling, SOPHOS_Gootloader_JS
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
Contacted infrastructure
- 157.90.183.190 - AS24940 Hetzner Online GmbH (Germany)
Observed indicators
- matomo.documentfoundation.org
- matomo.org
- 157.90.183.190
- https://matomo.documentfoundation.org/
- https://matomo.documentfoundation.org/plugins/CoreHome/images/favicon.png
- https://matomo.documentfoundation.org/plugins/CoreHome/images/applogo_256.png
- https://matomo.documentfoundation.org/plugins/CoreHome/images/applePinnedTab.svg
- https://matomo.documentfoundation.org/index.php?module=Proxy&action=getCss&cb=5340766355ae4b8bc6c25cc92e2f8555
- https://matomo.documentfoundation.org/index.php?module=Proxy&action=getCoreJs&cb=aea079dbb45f46869211d03b4e473334
- https://matomo.documentfoundation.org/index.php?module=Proxy&action=getNonCoreJs&cb=aea079dbb45f46869211d03b4e473334
- https://matomo.documentfoundation.org/index.php?module=Proxy&action=getUmdJs&chunk=0&cb=aea079dbb45f46869211d03b4e473334
- https://matomo.documentfoundation.org/index.php?module=Proxy&action=getUmdJs&chunk=1&cb=aea079dbb45f46869211d03b4e473334
- https://matomo.documentfoundation.org/index.php?module=Proxy&action=getUmdJs&chunk=2&cb=aea079dbb45f46869211d03b4e473334
- https://matomo.documentfoundation.org/plugins/CoreHome/javascripts/manifest.json
- https://matomo.org/
- https://matomo.documentfoundation.org/plugins/Morpheus/images/logo.svg?matomo
- https://matomo.documentfoundation.org/?module=Login
- https://matomo.documentfoundation.org/https://www.libreoffice.org/privacy
Other scans of matomo.documentfoundation.org (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - malicious
- 18 Aug 2026 - unknown
Questions about matomo.documentfoundation.org
- Is matomo.documentfoundation.org safe?
- No. MalwareAnalyzer scanned matomo.documentfoundation.org on 19 Aug 2026 and returned a malicious verdict with a score of 61 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with matomo.documentfoundation.org?
- 9 analysed samples communicate with this URL, including Container, RedLine.
- How was matomo.documentfoundation.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of matomo.documentfoundation.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan